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MEMORANDUM FOR: AI11 Community Security Group 


SUBJECT: Revision of Compartmentation Programs 


1. The Office of Security, CIA completed an extensive 
review of the CIA Security Program following the Kampiles 
Case and made a series of recommendations which the DCI 
reviewed and made comments on. A copy of that paper is 
attached. 


2. Many of the recommendations have ramifications 


beyond the CI ne DCI has directed the attention of 
[I Sspecial Assistant to the DCI (tasked 
Wi revising the Intelligence Community's Compartmentation 


Programs), to three of them associated with information 

control security (nos. 14, 16, and 23). will 25X1 
consider these recommendations as he moves 1s Group toward 
implementation of approved compartmentation programs. 


3. Other recommendations could impact on some areas 
of interest to the Community Security Group. Among these 
are recommendations 13, 15, 17, 21, 22, and possibly 4 (as 
it relates to reinvestigation at the end of probationary 
periods for new employees), 5 (as it relates to requirements 
for policy of investigative coverage and 5 year reinvestigative 
coverage of Industrial Contractor employees), and 25 (as it 
pertains to Automatic Data Processing security requirements). 


4. I am concerned, lest CIA's recommendations have 
unseen Community ramifications. I request CSG members to 
review the OS recommendations and make appropriate comments on 
implications they see in them for the Community. I would 
appreciate having by 5 January your written observations with 
an outline of procedures or actions we might take (or have 
forced upon us) to permit us ensure Community equities in 
what CIA now views as a CIA program. 
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C . “Shows De] worn notes 
ieee Se cunt Sees of Cin Sa cunby ho Gram 
Sas SUMMARY-.OF .RECOMMENDATIONS 
Personnel Security 


. 2... It is recommended that the current.CIA Regulation 
25X1 . [ be revised to: 
(a) Clearly charge individual supervisors in this OK 
. Agency with basic responsibility for the secu- 


rity supervision of employees under their pur- 
view. ; ; ‘ . : 7 = : : ~_ : 
ae : 7 7 | ok tell 
- (b) Require the appointment of one or more Career 4 oy 


. Security Officers to each major Agency component 
ee - to assist Agency ‘supervisors in fulfilling their Lae 
os . security supervisory responsibilities. At Copland f 

(c) Charge Career Security Officers with the respon- ~ 


. ) balled sibility of selecting Designated Security Officers 
Fhthe® each component who, as their subordinates, 
4 
” 


will assist them in fulfilling their responsi- 


On bilities, and that their selection be concurred 


in by both the component head and the Director of 


Security. . 
(d) Require that each Designated Security Officer OK. 
undergo an appropriate period of training in the 


Office of Security before he assumes his duties. 
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(e) Include as the first two responsibilities of 
the Career Security Officer: 
(1) the establishment and maintenance of methods 
VY for becoming aware of significant personnel 
) ie situations as a first priority; and 
(2) the implementation of a CIA Security Awareness 
Program, as developed by the Office of eae 
on a regular basis but no less than twice per 
year. . | yreLk vpn Ale # 
2, It is recommended that Bay a of Security be~ 
Authorized, in coordination with the heads of appropriate Agency 
components, teo~determine where he wishes to have Career Area 
‘Security Officers placed at Headquarters and in domestic and 
foreign installations; after which appropriate action will be 
taken to implement his determinations. 
NOTE: Because of the time constraints paaced upon the . 
| authors of this report, it is not possible at this 
time to state precisely how many new Career Security 
Officer positions would be ay es to implement 
this program. KEL packer eas om /&) 
3. It is recommended that a new group be established and 
properly staffed within the OS to include all indoctrination 


and education functions, patterned after the program in. 
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existence at NSA. The functions of the new group would 

include: EOD and exit briefings; serving as a focal point. 

for consultation and channeling personnel problems to the 

proper components; guidance to employees regarding outside 

activities: briefings and debriefings prior to PCS/TDY over- 

seas assignments, private travel and access to sensitive 

compartmented information; the establishment of an on-going A 

Presuming that some existing resources could be ZY. 4 ie! 
Caner 


approximately four to six new positions would be required tore 


security awareness program. 
reallocated in establishing this group, it is estimated that 


achieve comparability with the NSA program. Gt 5 Ve aae 
4. It is recommended that probationary employees be 

screened prior to becoming career employees by a combined 

review by their. Career Service, OMS, OS, and OP. Such screen- 

ing would include a review of fitness reports and Supervisory | 

comments and the recommendation of the Career Service and OP, 

an updating and review of medical records, and a reinvesti- 


gation and EOD-type polygraph by OS. It is anticipated that 


ln prop eae 


5. It is recommended that apolicy be adopted requiring 


this recommendation would ae addition apes soley 


resources in OS, OMS, and OP. 


that Industrial Contractor employees undergo an investigation 
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6. It is recommended that a minimum of six additional 


field agents and one case supervisor be approved to handle 


approximately 2,800 additional cases annually. 


Physical Security | 
7. %&In order to obtain a desired degree of compound access 
control? Gate #2 (West Lot) and Gate #3 (George Washington 
Peiiay) should be restricted to badged employees only. All 
unbadged entry should be directed to Gate fl (Route 123) where 
a visitor processing area would’ be developed. This area, to 
the right of Gate #1, should be examined by a traffic-design 
consultant in order to effect the desired level of control 
without significantly hindering the conduct of official 
business. The ultimate solution for this area should take 
into account the need to verify an individual's stated purpose 
_ for visiting the Agency. The processing area should be capable 


of handling, with an acceptable level of inconvenience, all 
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categories of unbadged visitors. Special parking areas 
would be required in the immediate area and consideration ve. 
should be given to a compound shuttle bus system to bring 
‘visitors to the Main Entrance after initial screening. 
' Additionally, the use of temporary and permanent vehicle 


passes to facilitate the passage of frequent visitors 


should be considered during this study. 


10. It is recommended that a complete review of all 
VNE badge holders be undertaken with the respective sponsoring | 
offices. Procedural constraints on VNE badge issuance, such 
as sponsoring office justification memoranda and Office of 
Security review mechanisms, should be reassessed and signifi- 
cantly modified. The continuing responsibility of a sponsor- 


ing individual for a VNE badge ay) must be wd 


(Dose ~ 200 one ALYVE Gof 4 ia We 
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established and accepted. The reviewing role of the Office of 


Security must be affirmed and exercised. The categories of 


individuals presently holding VNE badges should be scrutinized, 


and any inappropriate category, such as IBM or Xerox maintenance 


personnel, changed to a proper badge. 


12. %It is recommended that CIA institute a program for 
the selective and progressive elimination of all obsolete 
security container safe files from the Agency's inventory, 
beginning with those currently located at Agency facilities 
outside of the Headquarters Building. This should be funded 
by the Office of Logistics and carried out in an MBO format. 
Information Control Security 

. 13. It is recommended that the DCI appoint an action 


group to define precisely which intelligence requires TOP 


SECRET classification, both within and otittside the compart- . 


mentation systems, and provide specific, detailed guidance 
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with the intent of reserving TOP SECRET classification for L 


information of truly extraordinary sensitivity and imposing 


strict accountability and rigid physical security upon 


those items determined to be TOP SECRET, both collateral 


and SCI. 


14. It is recommended that strict accountability b 
imposed upon TOP SECRET SCI materials, identical to that 
required for noncompartmented TOP SECRET, but within compart- 
mented channels. This should include TOP SECRET SCI electrical 
message traffic. | 


15. It is recommended that a zero-based review of the 


0K 


dissemination of sensitive intelligence reports and publications 
be conducted, to ensure that all.subscribers ave a true need 
for the materials they receive. It is further recommended 
that revalidation of these requirements be provided in January 
of each year, with approval certified first at the Branch and i" 
then at the Division level of the originating office. User 
profiles should be superimposed on the distribution of all 
intelligence publications to provide a need-to-know filter 
limiting the iidividdal’s topical access. Pre-printed covers 
for intelligence publications should reflect the actual clas- 
sification and compartmentation of the material they cover. 

16. It is recommended that procedures be established to 


permit readers to challenge serious anomalies in classification 
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or compartmentation, requiring prompt reevaluation and 
response by the originator. 

17. It is recommended that an intensive review of ak 
current registry operations, policies, procedures and 
requirements be undertaken. 


18. It is recommended that the responsibility for 7 
porsey and procedural guidance of basic regi euay functions . 
be removed from the individual components and placed under 
central authority. 
19. It is recommended that formal training in security OK 


document control procedures be made mandatory for all 


registry personnel and others assigned responsibility for 


Fe 


controlling sensitive documents. ( : 

20. .It is recommended that a career service be created 7 DCT. 
to include all registry officers and information control = 
specialists. . 

21. It is recommended that all office copiers and micro- yk 
form printers be located in registries or document control — 
centers, to be operated only by information control specialists 
who will ensure that all copies of controlled documents are 
properly registered, controlled and stored. 


22. It is recommended that all controlled documents 


(TOP SECRET, SCI, etc.) be transmitted only from registry 
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to registry, and that they be controlled and held in registry 
woudune rooms, where they may be read by those requiring OK 
access. In fully justified cases, controlled documents 

might be charged out to individuals for brief periods, with 


prompt follow-up on documents not promptly returned. 


23. To supplement Executive Order 12065, it is recommended 
that TOP SECRET ieeia vaedde documents, once defined as recom- /[ 
mended previously, be inventoried annually, whether SCI or non- 
SCI. All. Intelligence Community elements should initiate an 
ongoing program to spot-inventory controlled documents, whether 
held by individuals, components, or registries. . | 

24% It is recommended that the Office of Security create rae 
a unit to conduct security audits of Agency components, similar PACH 
to the recently-instituted Industrial Security Audits. This Btr id 


unit should also conduct spot inspections of eon troried oraaee is 


ment holdings whether they be accountable to individuals, 


components, or registries. 


25. It is recommended that security requirements be 2 


DICE. 


included in ODP standards to enhance security control of 


Classified data by need-to-know profiles for topical access to 


data; by utilizing user codes and ID numbers to access data; 

by creating audit trails for all data output, and by applying 
classifications, copy numbers and other controls to data output. 
It is further recommended that all Agency ADP systems be designed 


in accordance with ODP programming’ and production standards. 
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26.. It is recommended that a CIA component be given the 
responsibility to monitor becinobogieat advances in the ADP ? 
field for the eventual development of a central, formalized Nel 
computer-operated document accountability system for registry 


use and for use at remote terminals. 
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